Hong Kong’s Securities and Futures Commission has told licensed corporations and SFC-licensed virtual asset service providers to stop using one-time passwords for client login and device binding within 12 months.

The regulator wants phishing-resistant authentication methods, including passkeys and stronger device binding, plus better monitoring of suspicious logins, trades and withdrawals.

This matters because crypto security is being pushed from wallet custody into the account-access layer. A licensed platform can have strong custody controls and still lose users through login spoofing.

The second-order risk is implementation quality: passkeys reduce phishing exposure, but rushed device binding or poor recovery flows can lock out legitimate users or create new support-side attack paths.

Next, watch which Hong Kong platforms move first and whether other Asian regulators copy the OTP phase-out model.